Microsoft releases security updates to address a Windows Defender-related “RoguePlanet” vulnerability disclosed in mid-June 2026. Multiple reports say the issue is tracked as CVE-2026-50656 and is classified as a local privilege escalation flaw that can allow an authenticated attacker to gain SYSTEM-level privileges on affected Windows systems. Sources describe the problem as residing in the Microsoft Malware Protection Engine (mpengine.dll), which underpins scanning, detection, and cleaning for Microsoft antivirus and Defender capabilities.

According to the reporting, the vulnerability involves improper link resolution before file access, which can be triggered by low-complexity attack paths. The fix is delivered through Microsoft’s security patching process, with SecurityWeek noting that the remediation is provided via a Microsoft Malware Protection Engine update. Other outlets describe the patch as released through a subsequent cycle after the vulnerability details became publicly available on or around June 10, and reference it as part of Microsoft’s Patch Tuesday updates.

Help Net Security and other sources state the affected platforms include Windows 10 and Windows 11. The reported vulnerability has a CVSS score of 7.8 and is addressed by Microsoft in the released update(s).